JWT Verify — Reference
Verify a token before considering its claims for application decisions.
Verify a token before considering its claims for application decisions.
Before you begin
Section titled “Before you begin”- A Server Connect action. Test security behavior with an isolated test account or test-only token/key, not production credentials.
JWT Verify
Section titled “JWT Verify”Verify a token before considering its claims for application decisions.
Settings
Section titled “Settings”| Setting | Meaning and example |
|---|---|
| Name | Names the verification result. A successful result is the payload, not the full decoded header/signature envelope. |
| Token | The JWT string to verify. Do not substitute a previously decoded object. |
| Key | The verification key: the matching shared secret for HS tokens or public key for RS tokens. Use a key and accepted algorithm from trusted configuration, not values chosen by the incoming token. |
| Throw Error | In Node.js, on failure this either throws or returns an object containing error; the default is false. In the installed PHP module, verification exceptions are caught and the result is null; this flag is not applied in the same way. |
Verification example
Section titled “Verification example”Verify a known test token, then repeat with the wrong key and a modified payload. Node.js should return payload on success and either throw or return {error:…} on failure. PHP returns null for a caught verification failure. In particular, a truthy Node.js result object is not sufficient evidence of success.
Behavior and limits
Section titled “Behavior and limits”The inspector exposes Token, Key and Throw Error, not a complete token-acceptance policy. Enforce issuer, audience, time and allowed-algorithm requirements from trusted configuration. The installed PHP helper checks signature and expiration but does not implement equivalent audience/issuer/not-before checks. Do not treat this step alone as a complete authorization policy.
Use the complete authentication flow
Section titled “Use the complete authentication flow”Use the security and login guides for the surrounding provider, form, session and server-access configuration.
Check your result
Section titled “Check your result”You can configure the documented fields and distinguish a successful result from the failure or limitation described here.